Comment no DANE or RPKI for email (Score 1) 11
so they did not implement DANE or RPKI
if you delegate you have a serious problem
irony is they use route53 so its a single click solution they just did. not,,,,
silly get on it
also no HSTS and one of your mail servers does not offer STARTTLS (they use google but not the secure DNSSEC settings) and the domain does not have CAA.
faarrk did no one raise this with them ? seems unlikely.... seems like bonus got in the way of security
JJ